Advisories ยป MGASA-2021-0093

Updated openjpeg2 packages fix security vulnerability

Publication date: 02 Mar 2021
Modification date: 02 Mar 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-27844

Description

A flaw was found in openjpeg's src/lib/openjp2/t2.c in versions prior to 2.4.0.
This flaw allows an attacker to provide crafted input to openjpeg during
conversion and encoding, causing an out-of-bounds write. The highest threat
from this vulnerability is to confidentiality, integrity, as well as system
availability. (CVE-2020-27844).
                

References

SRPMS

7/core